CVE-2021-25249: Trend Micro Apex One TmCCSF Out-Of-Bounds Write Privilege Escalation Vulnerability
An out-of-bounds write information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Other sources
This vulnerability allows local attackers to escalate privileges on affected installations of Trend Micro Apex One. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within TmCCSF.exe. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-25249?
CVE-2021-25249 is a privilege escalation vulnerability in Trend Micro Apex One.
How severe is CVE-2021-25249?
CVE-2021-25249 has a severity score of 7.8 out of 10, which is considered high.
Who is affected by CVE-2021-25249?
Users of Trend Micro Apex One 2019, Trendmicro Officescan XG SP1, and Trendmicro Worry-free Business Security 10.0 SP1 are affected by CVE-2021-25249.
How can an attacker exploit CVE-2021-25249?
The attacker must first obtain the ability to execute low-privileged code on the target system to exploit CVE-2021-25249.
Are Microsoft Windows systems vulnerable to CVE-2021-25249?
No, Microsoft Windows systems are not vulnerable to CVE-2021-25249.
How can I fix CVE-2021-25249?
Apply the necessary security updates provided by Trend Micro to mitigate the vulnerability.